Skip to main content

Budget

Struct Budget 

Source
pub struct Budget { /* private fields */ }
Expand description

Shared between an engine’s runtime and its interrupt handler.

Records why execution was interrupted rather than leaving it to be inferred from the engine’s own exception or trap text. QuickJS, for instance, reports an interrupt as an ordinary Error whose message happens to be “interrupted”; keying behavior off that string would make the difference between “your rule looped forever” and “your rule threw” depend on wording this project does not control. A different engine’s own interrupted-execution signal would be exactly as unreliable to string-match, for the same reason.

Implementations§

Source§

impl Budget

Source

pub fn new(clock: Arc<RunClock>) -> Arc<Self>

Build a budget enforcer sharing the run’s clock.

Source

pub fn arm(&self, rule_timeout: Duration)

Start the clock on one invocation.

Source

pub fn disarm(&self)

Stop enforcing an invocation budget.

Source

pub fn pause(&self) -> Paused<'_>

Stop charging the current invocation while the host does work on its behalf.

Returns a guard; the invocation resumes with exactly the time it had when the guard was taken, measured from wherever the run clock is when the guard drops.

§Why not disarm followed by arm

Budget::arm takes a fresh rule_timeout and also clears Budget::take_trip’s record. Re-arming after a provider call would therefore hand the rule a whole new allowance on every question it asks — a rule asking a hundred type questions would be bounded by nothing — and would erase a global-budget trip that had already been recorded, turning a run timeout into silence. This carries the remainder instead, so a rule’s own budget still bounds a rule’s own code and nothing else.

The global check at Budget::should_interrupt is untouched: a paused invocation is still inside a run, and a run that has overrun must still stop.

Nesting composes rather than being forbidden, which costs no runtime check: an inner pause reads an already stopped clock as disarmed and so restores nothing on drop, leaving the outermost guard — the only one holding a real remainder — to resume.

Source

pub fn should_interrupt(&self) -> bool

Whether execution should stop now, recording why. Called by the engine’s interrupt handler, so it runs often and must stay cheap.

Source

pub fn take_trip(&self) -> Option<Trip>

Which budget was breached, if any. Clears the record.

Source

pub fn clock(&self) -> &RunClock

The run clock this budget was built from.

Trait Implementations§

Source§

impl Debug for Budget

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.